Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Mageia 7 MGASA-2020-0159 Moderate: Librsvg Denial Of Service

mageia
Calendar Grey April 5, 2020
Dist Mageia Esm H88
Recent updates to the librsvg packages in Mageia have fixed a severe denial of service vulnerability. For more details about the patch, check the official documentation
The updated packages fix a security vulnerability: In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the...

Summary

The updated packages fix a security vulnerability:
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially. (CVE-2019-20446)

References

- https://bugs.mageia.org/show_bug.cgi?id=26313

- http://lists.suse.com/pipermail/sle-security-updates/2020-March/006583.html

- - https://www.cve.org/CVERecord?id=CVE-2019-20446

Resolution

SRPMS

- 7/core/librsvg-2.45.5-3.1.mga7

Publication date: 05 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0159.html
Type: security
CVE: CVE-2019-20446

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here